You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用EC2身份访问Requester Pays S3桶遇凭证缺失错误求助

Why Do I Need Credentials to Access a Requester Pays S3 Bucket from EC2?

Great question—this is a super common point of confusion when working with Requester Pays buckets! Let’s break down why you’re seeing that Unable to locate credentials error, even though you’re accessing the bucket from an EC2 instance.

First, Let’s Clarify What Requester Pays Actually Does

Requester Pays shifts data transfer costs (like data out from S3 to your EC2 instance) from the bucket owner to the person making the request. But it doesn’t eliminate the need for AWS to verify who you are—here’s why:

1. AWS Needs a Way to Bill You for the Costs

Even if you’re on EC2, AWS can’t just charge "the EC2 instance" directly. It needs a valid AWS identity (an IAM user or IAM role attached to your EC2 instance) to associate those transfer costs with. Without credentials, AWS has no way to link the request to a billing account, so it rejects the request outright.

2. EC2 Instances Don’t Have Implicit Access to S3

You might assume your EC2 instance can access S3 by default, but that’s not true. EC2 only gets automatic S3 access if you’ve attached an IAM role to the instance. If you haven’t done that, the AWS CLI running on your instance has no credentials to use, hence the error you’re seeing:

Unable to locate credentials. You can configure credentials by running "aws configure"

3. Permissions Still Apply (Even When You’re Paying)

The bucket owner still needs to grant your identity permission to access the bucket. Requester Pays doesn’t override bucket policies or ACLs—AWS needs to verify that you’re allowed to list or download objects from the bucket, even if you’re willing to pay for the transfer. Without credentials, there’s no way to check this authorization.

How to Fix This

To get your command aws s3 ls --request-payer requester s3://requester-pays-bucket/ working, you have two secure options:

  • Attach an IAM Role to Your EC2 Instance: Create an IAM role with permissions like s3:ListBucket and s3:GetObject for the target Requester Pays bucket, then attach it to your EC2 instance. The instance will automatically pick up temporary credentials, so you won’t need to run aws configure.
  • Use IAM User Credentials (Less Recommended): Run aws configure on your EC2 instance and enter credentials for an IAM user that has the necessary permissions to access the bucket. IAM roles are better here because they avoid storing long-term credentials on your instance.

Just make sure the bucket’s policy explicitly allows your IAM identity to access it—something like this (replace placeholders with your details):

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::YOUR_ACCOUNT_ID:role/YOUR_EC2_ROLE"
      },
      "Action": ["s3:ListBucket", "s3:GetObject"],
      "Resource": [
        "arn:aws:s3:::requester-pays-bucket",
        "arn:aws:s3:::requester-pays-bucket/*"
      ]
    }
  ]
}

内容的提问来源于stack exchange,提问作者Nick Chammas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:14:09